Denying commands in sudoers

Neil Watson tlug-neil-8agRmHhQ+n2CxnSzwYWP7Q at public.gmane.org
Tue Jul 25 15:37:15 UTC 2006


Solved my own problem:

# Cmnd alias specification
Cmnd_Alias      DENY_CMD = /bin/su root, /bin/su - root

nhwatson ALL = ALL, !DENY_CMD

Of course this is not secure.  There are many ways for me to still
become root.

-- 
Neil Watson             | Gentoo Linux
System Administrator    | Uptime 15 days
http://watson-wilson.ca | 2.6.16.19 AMD Athlon(tm) MP 2000+ x 2
--
The Toronto Linux Users Group.      Meetings: http://tlug.ss.org
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://tlug.ss.org/subscribe.shtml





More information about the Legacy mailing list